Skip to content
CISA Adds CVE-2008-0015 to KEV Catalog Due to Active Exploitation

CISA Adds CVE-2008-0015 to KEV Catalog Due to Active Exploitation

First seen 18 Feb 2026, 12:23 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

CISA has added the long-standing Microsoft Windows vulnerability CVE-2008-0015 to its Known Exploited Vulnerabilities (KEV) catalog following evidence of active exploitation. This flaw, affecting the Windows Video ActiveX Control, allows for remote code execution (RCE) and poses a significant risk to users. The vulnerability was first disclosed in 2008 and has now been confirmed as actively exploited as of February 17, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 209d ago How this analysis works

Timeline

2009-07-07
CVE-2008-0015 published
2026-02-17
CVE-2008-0015 added to CISA KEV catalog due to active exploitation
2026-02-18
CISA announces addition of CVE-2008-0015 to KEV catalog

More articles in this cluster (2)

Following this threat?

Track CVE-2008-0015 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed